What it is
Falcon is CrowdStrike’s endpoint platform. A lean sensor supplies the events from the device; the analysis runs in the vendor’s cloud. What gets judged is behaviour rather than files: not “do I know this signature”, but “why is this process reading another one’s memory”.
What it is for
Estates that choose their endpoint security independently of the rest of the stack. Falcon ties you to no platform licence and covers Windows, macOS and Linux with the same sensor.
The second point is growth: EDR is one module of several. Identity protection, cloud workloads and threat intelligence come out of the same console when they are needed.
What to watch
The modules are licensed individually, and the feature set depends on the package you bought. What a quote calls “Falcon” is therefore not always the same Falcon.
And as with any EDR: the recording is worth as much as the team looking at it. Where there is none, managed detection and response belongs in the plan from day one.